Senior Security Architect — Mobile Banking
Platforms
Customer-facing digital banking ·
Security-by-design · Mobile, API, Cloud, Identity, Fraud & DevSecOps
Millions of people open a banking app and
expect it to just work. Fast. Simple. Safe. That last part is not a slogan. It
is the architecture.
This role owns the security design of a
large-scale, customer-facing mobile banking platform — iOS, Android, web, APIs,
identity, cloud, payments, and the pipelines that ship change every sprint.
You are the person who decides how trust
is built into the product before a line of code hits production.
Role Purpose
The Senior Security Architect is
accountable for the end-to-end security architecture of a large-scale,
customer-facing mobile banking platform. The role defines, governs, and
continuously evolves security across mobile applications, APIs, identity
platforms, cloud infrastructure, backend services, shared platform
capabilities, and DevSecOps delivery pipelines.
This role acts as the security design
authority across platform teams and delivery squads, ensuring the mobile
banking platform achieves world-class standards for customer trust, cyber
resilience, regulatory compliance, privacy, fraud resistance, and secure
customer experience.
Key Responsibilities
- Own the end-to-end security architecture
for a large-scale, customer-facing mobile banking platform.
- Define and govern security across mobile
apps, APIs, identity platforms, cloud infrastructure, backend services, shared
platforms, and DevSecOps pipelines.
- Architect strong customer authentication
using PIN, biometrics, device-bound cryptographic keys, risk context, and
transaction-level authorization.
- Design PIN-based authentication models
where PINs unlock cryptographic keys and are never stored or transmitted.
- Define biometric-first authentication
using Face ID, Touch ID, and platform biometrics through secure enclave and
hardware-backed mechanisms.
- Govern secure use of mobile keystores and
secure enclaves, including iOS Secure Enclave and Android Hardware Keystore.
- Ensure biometrics are used only for local
cryptographic key release and never treated as raw credentials.
- Define integration with enterprise key
vaults and HSMs for signing, encryption, certificate handling, and key
lifecycle management.
- Own OAuth 2.0, OpenID Connect, PKCE,
secure token storage, token rotation, and device-bound session models for
mobile and web channels.
- Define API, Backend-for-Frontend, and
service security patterns aligned to Zero Trust principles.
- Lead threat modelling across onboarding,
authentication, payments, card management, account servicing, and other
sensitive customer journeys.
- Translate threats into architecture
patterns, security controls, non-functional requirements, and architecture
decision records.
- Embed Security-by-Design into HLDs, LLDs,
architecture decision records, release governance, and delivery assurance
forums.
- Define DevSecOps guardrails including
SAST, DAST, dependency scanning, secrets management, container scanning, IaC
security, and secure release gates.